We've deployed this scenario on Linux + Free S/Wan running snort on all physical interfaces and all ipsecX interfaces for folks. The fastest wire-speed we've had on one of these deployments is T1, and a PIII450 has handled VPN traffic at wirespeed even with the added load of snort. Sorry I don't have any higher-bandwidth benchmarks for you.